An Industrial Cyber-Physical System Attack Detection Method Based on a Two-Stage Autoencoder
By adopting a two-stage autoencoder detection method in ICPS, the problem of multi-link or multi-device FDI attack detection is solved, and effective detection of multiple devices and multiple links being attacked at the same time is realized, which improves the security of ICPS.
Patent Information
- Application Number
- CN202210276375.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-03-21
AI Technical Summary
The prior art is difficult to effectively detect and defend against FDI attacks from multi-link or multi-device in industrial information physics systems (ICPS), especially multi-point false data injection attacks (MFDIA), which can bypass traditional bad data detection mechanisms.
The attack detection method based on two-stage autoencoder is adopted. By establishing a multi-device and multi-link FDI attack model, the autoencoder technology is introduced to build a generative adversarial model, and a two-stage training method and attack detection algorithm are designed to detect FDI attacks of multi-link and multi-device.
This method can effectively detect the attacks of multiple devices and multiple links at the same time, improve the security and reliability of ICPS, and avoid the problems of high false alarm rate and low detection accuracy in traditional methods.
Smart Images

Figure CN114721264B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial cyber-physical system (ICPS) security control and operation, and in particular to an industrial cyber-physical system attack detection method based on a two-stage autoencoder, which is applied in ICPS to solve the problem of FDI attack detection on multiple links or multiple devices implemented by attackers. Background Art
[0002] With the increasing maturity of IT technology and Cyber Physical System (CPS) technology, CPS has been applied to more and more fields. With the development and maturity of industrial wireless sensor networks, it has also been applied to industry. The application of cyber physical systems in industry has formed industrial cyber physical systems (ICPS). It has realized the intelligence and informatization of industrial systems, so that relevant staff no longer need to go to the industrial site to perform manual physical operations, but can use the central computer and data acquisition system (SCADA) combined with the remote management characteristics of ICPS to implement the work of issuing instructions and collecting data on site. This intelligently written operation benefits from the combination of the physical world and information system of industrial production. At the same time, it brings convenience to hackers with ulterior motives. The way of connecting physical processes with information space greatly increases the possibility of ICPS being attacked by different types of network attacks.
[0003] At present, ICPS can be divided into three layers: perception layer, network layer and control layer. The control layer is equivalent to the brain of ICPS, responsible for issuing management and control commands for the system, analyzing and processing the data transmitted by the perception layer; the network layer is mainly responsible for information interaction and data transmission between the control layer and the perception layer; the perception layer is mainly composed of field equipment and controller groups such as industrial sensors and programmable logic controllers (PLC), which mainly perceive industrial machine information and issue high-speed real-time control instructions. In industrial systems, controllers such as PLCs are used to realize the low-level high-speed real-time control functions, which are particularly important for industrial control. Control devices and field equipment such as sensors and actuators form a fieldbus control network. Attacks on sensors and controller actuators in the perception layer will deceive the control layer and make the control layer issue seemingly normal erroneous commands. Accidents occur unknowingly at the production site, affecting the normal operating life of the actuators and even causing casualties. The main attack threats against the perception layer of ICPS are FDI attacks and DoS attacks. Among them, FDI attacks are more harmful and easier to deceive the system than other attacks.
[0004] With the relevant knowledge of the target large-scale process industrial system that requires long-range data transmission, the attacker first intercepts and then tampers with the data packets, and finally achieves the purpose of deceiving the system status, injecting false data into the target system, causing it to deviate from the normal stable state, or even causing the system to crash and cause personal accidents. Due to the vulnerability and importance of facilities such as power grids and water treatment systems, the false data injection attack itself and its detection and defense in ICPS have become hot research issues.
[0005] In recent years, research on the detection of industrial cyber-physical systems has mainly focused on the following two directions: based on process data analysis and based on network traffic analysis.
[0006] (1) Based on network traffic analysis: Fluctuations in network traffic usually indicate changes in the state of the ICPS, which makes attack detection based on network traffic analysis possible. Traditional detection methods based on network traffic analysis usually extract information such as node port traffic, traffic duration, and the average time interval between adjacent packets, and then perform data mining on this information to determine abnormal behavior of nodes in the system. The purpose of these technologies is to establish a complex relationship between network traffic and system behavior, and use this relationship together with current network traffic data to determine the security status of the target system. When the network traffic is high, attack detection methods based on network traffic may miss the attack being launched when monitoring data packets. On the other hand, if the network attack behavior does not violate the communication protocol used by the system and equipment, the operational behavior of the detected ICPS cannot be inferred from the network traffic information.
[0007] (2) Based on process data analysis: Since FDI attacks mislead controllers to make wrong decisions by tampering with process data and ultimately damage the system, process data information is also one of the main bases that can be considered in ICPS attack detection. In addition, some researchers have also used data-driven methods of deep learning to utilize the temporal and spatial correlation of sensor data to help identify forged data. The anomaly detection method based on process data system modeling establishes a system internal mechanism model and combines it with operating data for anomaly detection. The effectiveness of this method depends on the accuracy of the established model. The industrial production process mechanism of large-scale ICS is complex, and there are often multiple variables and strong coupling between the production processes, making it difficult to establish an accurate physical model.
[0008] Many researchers have proposed many IDSs to combat the intrusion of ICPS. However, most of the IDSs proposed earlier have a high false alarm rate. For existing models, these two types of attacks generally seem to have low detection accuracy. High-level attackers do not simply attack a single device, but attack multiple devices or multiple links at the same time, which is called Multipoint Fake Data Injection Attack (MFDIA). Due to the interaction between the devices in ICPS, the effects of multi-point attacks on the devices may offset each other, and it also becomes a kind of hidden attack, which can bypass the bad data detection mechanism. In this case, the known threshold detection method cannot effectively solve the problem. Summary of the invention
[0009] In order to solve the problem of multi-link and multi-device FDI attack detection in ICPS, the present invention designs an attack detection method based on a two-stage autoencoder.
[0010] The technical solution adopted by the present invention to solve its technical problem is:
[0011] A FDI attack detection method based on a two-stage autoencoder includes the following steps:
[0012] 1) Establish a multi-device, multi-link FDI attack model;
[0013] 2) Introducing autoencoder technology;
[0014] 3) Construct a generative adversarial model based on autoencoder;
[0015] 4) Design a two-stage training method;
[0016] 5) Design attack detection algorithm;
[0017] 6) Design an attack detection method based on a two-stage autoencoder.
[0018] In step 1), generally speaking, multi-link and multi-device FDI attacks can be divided into the following two types according to their occurrence locations:
[0019] ① Controller-actuator link (or device) attack:
[0020]
[0021] where δ 1 is the attack vector, u 1 is the output value of the controller, is the input value of the actuator (i.e., the received value). In this type of attack, the attacker tampers with the controller's command data. The injected attack data is specifically used to affect the actuator's task execution, causing it to perform seemingly correct erroneous operations to deceive the controller.
[0022] ②Sensor-controller link (or device) attack:
[0023]
[0024] where δ 2 is the attack vector, y 1 is the sensor output, is the input value of the controller (that is, the actual received value). This type of attack mainly involves the attacker tampering with the information returned by the sensor to the controller, interfering with the controller's data reception and thus affecting the issuance of its adjustment instructions, deceiving the controller and causing it to issue control adjustment instructions that are inconsistent with the actual situation in the next step.
[0025] The actuator and sensor operation data generated by these two attacks can be viewed as long-term time series vectors:
[0026]
[0027] In step 2), the autoencoder is an unsupervised neural network algorithm that can learn the implicit features of the input data (vector) and transform it from high-dimensional data into multi-dimensional data, which is data dimensionality reduction. This step is called encoding. At the same time, the new features learned can also reconstruct the original input data, which is called decoding. In addition to dimensionality reduction, the autoencoder can also act as a feature extractor. Here, it is used as a feature extractor to learn the features of the multi-dimensional time series data of sensors and actuators, so that it can reconstruct the operating data of sensors and actuators when the system is in normal operation.
[0028] Building an autoencoder requires three tasks: building an encoder, building a decoder, and setting a loss function to measure the information lost due to encoding (compression). The encoder is responsible for receiving the input vector X and converting the input into a reduced-dimensional encoding vector Y through the h function:
[0029] Y=h(X) (4)
[0030] The decoding step takes the encoded vector Y as its input and obtains the reconstructed vector through the function f:
[0031]
[0032] Define the error err as the sum of the original input X and the reconstructed vector The difference between The goal of training is to reduce the mean squared error (MSE).
[0033] Going further, in step 3) above: First, we need to understand the idea of generative adversarial networks. Generative Adversarial Networks (GAN) is a deep learning model consisting of a generator G and a discriminator D. First, G learns the probability distribution of a given input data set and generates artificial data that follows the same distribution. Then D calculates the similarity gap between the data generated by G and the real data. The smaller the gap value, the more similar the generated fake data is to the real original input. The entire adversarial learning process of GAN can be seen as a game process about optimizing the maximum and minimum values of the objective function V(D,G):
[0034]
[0035] It can be seen from formula (6) that for the generator G, it is necessary to deceive the discriminator D as much as possible, so it is necessary to maximize the discrimination probability D(G(z)) of D for the generated samples, that is, minimize log(1-D(G(z))). For D, its purpose is to distinguish the forged generated samples from the real samples as much as possible, so it is necessary to maximize log(1-D(G(z))). The construction steps of the autoencoder have been described in the above step 2). According to the described steps, two autoencoders need to be constructed. After both are trained, the reconstructed output decoded by one of the encoders is used as the input of the second encoder. That is, the first one is used as the generator and the second one is used as the discriminator to perform the adversarial discrimination process.
[0036] Furthermore, the above step 4) specifically includes:
[0037] Stage 1: The first half (i.e., encoding part) of the two autoencoder models are shared, using a common encoder network:
[0038] AE 1 =D 1 (E(X)),AE 2 =D 2 (E(X)) (7)
[0039] The input data X is compressed by the encoding part of the autoencoder to the latent space Y, and then reconstructed by the two encoders respectively until each autoencoder is trained to reconstruct the input vector, that is, to minimize the following two equations:
[0040]
[0041] Stage 2: Two autoencoders are trained in an adversarial manner, AE 1 Trying to trick AE 2 , and AE 2 The goal is to learn to distinguish which data is real and which data is reconstructed. 2 Able to identify real data and data from AE 1 Data, training AE 1 Tricking AE 2 , from AE 1 The output data is compressed again by the encoder to Y, and then by AE 2 Reconstruction, using the idea of adversarial training, AE 1 The goal is to minimize AE 2 The difference between the output and X, AE 2 The goal of AE is to maximize this difference. 1 Is the training successful in deceiving AE? 2 , while AE 2It is trained to distinguish between real data and data from AE 1 Output the reconstructed data:
[0042]
[0043] The error loss function is further expressed as:
[0044]
[0045] In this training architecture, the autoencoder serves a dual purpose. 1 Minimize the reconstruction error of X (stage 1), and also make X and AE 2 About AE 1 The output reconstruction error is the smallest (stage 2). 2 , and AE 1 Similarly, it minimizes the reconstruction error of sample X (stage 1), but it then makes AE 1 The reconstructed input data has the largest error (stage 2). The dual training objectives of each autoencoder can be expressed as a linear combination of equations (8) and (10):
[0046]
[0047]
[0048] Where n represents the training cycle. It should be noted that AE 2 It is not a discriminator of the adversarial network in the strict sense, because if its input is the original data, then equation (8) should be used to calculate the loss. 1 When reconstructing, its loss is calculated using equation (10). It should be noted that in the parameter update during the training process, a related optimization algorithm can be used. Here, a small batch optimization algorithm based on Adam optimization and gradient descent optimization is used.
[0049] Furthermore, in the above step 5), an attack detection algorithm is designed: according to the training method designed in step 4, in the detection phase (ie, the testing phase), the anomaly score is defined as:
[0050]
[0051] Where α+β=1 and is used to parameterize the trade-off between false positives and true positives. If α is greater than β, the number of true positives and false positives will be reduced. On the contrary, if α is taken to be less than β, the number of true positives will increase, but the number of false positives will also increase. α<β is represented as a high-sensitivity detection scenario, and α>β is represented as a low-sensitivity detection scenario. This parameterization scheme has great industrial significance. It allows a set of different sensitivity anomaly scores to be obtained during inference using a single trained model. A larger α corresponds to a greater emphasis on AE in the anomaly score. 1 The reconstruction error of the autoencoder, and a larger β corresponds to a greater emphasis on the AE 2 Reconstruction error of the autoencoder. The detection sensitivity can be readjusted without retraining the model. The parameterizable adjustment of α and β allows the sensitivity of the detection model to meet the requirements of a wide variety of production environments.
[0052] Finally, in step 6), we design an attack detection method based on a two-stage autoencoder. The entire attack detection method is divided into three steps:
[0053] Step 1: Data preprocessing. The training data set is normalized and divided into time series windows of length K. A univariate time series contains only one variable at each moment, while a multivariate time series contains multiple variables at each moment. 1 ,x 2 ...,x T},x∈R m In order to mathematically model the dependency between the current moment and the previous moment, we define X again: t , given a time window length K and time t: X t ={x t-(K-1) ,x t-(K-2) ,...,x t-1 ,x t The original time series Γ can be transformed into a time window sequence X = {X 1 ,…,X T} as training input.
[0054] Step 2: Model training. Model training is performed offline, aiming to capture the normal behavior of multivariate time series over a period of time and generate anomaly discrimination scores for each time window, taking care not to include a large amount of abnormal time period data after an attack.
[0055] Step 3: Attack detection. This step is performed using the model trained in step 2 (online). As new time windows are formed, the model generates anomaly scores Sc for each window. t, if it is higher than the given threshold λ, the time period corresponding to the new time window is the abnormal time period under attack.
[0056] In the present invention, it is considered that the attacker may obtain sufficient system structure knowledge of the ICPS to be attacked in advance, and then launch a high-level attack on the ICPS later, and simultaneously attack multiple devices or links, so that the measured data reflected by the system may be in the normal range without being discovered, but the actuator and other components are deceived by the attacker and affect the actual operation. From the perspective of adversarial learning, and considering the slow convergence of the generative adversarial network and the possible defects such as mode collapse, the generative adversarial network is abandoned and the adversarial idea is retained. An adversarial model based on an autoencoder is proposed to realize attack detection of multivariate time series. The first stage of model training only needs to train the encoder to minimize the normal reconstruction error. The second stage uses the adversarial idea to use one of the autoencoders as a generator and the second as a discriminator, thereby solving the shortcomings of the traditional generative adversarial network that is difficult to converge and mode collapse while achieving the detection purpose.
[0057] The advantages of the present invention are as follows: it utilizes the adversarial idea and combines the two-stage autoencoder introduced to form an attack detection method for multi-link and multi-device attacks, which not only retains the beneficial adversarial idea but also avoids the shortcomings of the generative adversarial network. It can detect the situation where multiple devices and multiple links are attacked at the same time without being discovered, ensure the normal operation of ICPS and improve the system security performance while detecting the attack. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 It is a schematic diagram of the attack model in the ICPS of the present invention;
[0059] Figure 2 is a schematic diagram of a conventional autoencoder of the present invention;
[0060] Figure 3 is a schematic diagram of stage 1 training of the present invention;
[0061] Figure 4 is a schematic diagram of stage 2 training of the present invention;
[0062] Figure 5 It is a schematic diagram of the detection phase of the present invention.
[0063] Figure 6 is a flow chart of the method of the present invention. DETAILED DESCRIPTION
[0064] The present invention will be further described below in conjunction with the accompanying drawings.
[0065] Reference Figure 1 to Figure 5, an industrial cyber-physical system attack detection method based on a two-stage autoencoder, comprising the following steps:
[0066] 1) Establish a multi-device, multi-link FDI attack model;
[0067] Generally speaking, multi-link and multi-device FDI attacks can be divided into the following two types according to their occurrence locations (see Figure 1):
[0069] ① Controller-actuator link (or device) attack:
[0070]
[0071] where δ 1 is the attack vector, u 1 is the output value of controller 1, is the input value of actuator 1 (i.e., the received value). In this type of attack, the attacker tampers with the controller's command data. The injected attack data is specifically used to affect the actuator's task execution, causing it to perform seemingly correct erroneous operations to deceive the controller.
[0072] ②Sensor-controller link (or device) attack:
[0073]
[0074] where δ 2 is the attack vector, y 1 is the output value of sensor 1, is the input value of controller 2 (that is, the actual received value). This type of attack mainly involves the attacker tampering with the information returned by the sensor to the controller, interfering with the accuracy of the controller's data reception, thereby affecting the issuance of its adjustment instructions, deceiving the controller, and causing the controller to issue control adjustment instructions that are inconsistent with the actual situation in the next step.
[0075] The actuator and sensor operation data generated by these two attacks can be viewed as long-term time series vectors:
[0076]
[0077] 2) Introducing autoencoder technology
[0078] An autoencoder is an unsupervised neural network algorithm (such as Figure 2), it can learn the implicit features of the input data (vector), turning it from high-dimensional data into multi-dimensional data, which is data dimensionality reduction. This step is called encoding; at the same time, the new features learned can also reconstruct the original input data, which is called decoding. In addition to dimensionality reduction, automatic encoding can also act as a feature extractor. Here, it is used as a feature extractor to learn the features of the multi-dimensional time series data of sensors and actuators, so that it can reconstruct the operating data of sensors and actuators when the system is in normal operation.
[0079] Building an autoencoder requires three tasks: building an encoder, building a decoder, and setting a loss function to measure the information lost due to encoding (compression). The encoder is responsible for receiving the input vector X and converting the input into a reduced-dimensional encoding vector Y through the h function:
[0080] Y=h(X) (4)
[0081] The decoding step takes the encoded vector Y as its input and obtains the reconstructed vector through the function f:
[0082]
[0083] Define the error err as the sum of the original input X and the reconstructed vector The difference between The goal of training is to reduce the mean squared error (MSE).
[0084] 3) Building a generative adversarial model based on autoencoder
[0085] First of all, we need to understand the idea of generative adversarial networks. Generative adversarial networks (GAN) are a deep learning model consisting of a generator G and a discriminator D. First, G learns the probability distribution of a given input data set and generates artificial data that follows the same distribution. Then D calculates the similarity gap between the data generated by G and the real data. The smaller the gap value, the more similar the generated fake data is to the real original input. The entire adversarial learning process of GAN can be seen as a game process about optimizing the maximum and minimum values of the objective function V(D,G):
[0086]
[0087] As can be seen from formula (6), for the generator G, it is necessary to deceive the discriminator D as much as possible, so it is necessary to maximize the discrimination probability D(G(z)) of D for the generated samples, that is, minimize log(1-D(G(z))). For D, its purpose is to distinguish the forged generated samples from the real samples as much as possible, so it is necessary to maximize log(1-D(G(z))). The construction steps of the autoencoder have been described in the above step 2). According to the described steps, two autoencoders need to be constructed. After both are trained, the reconstructed output decoded by one of the encoders is used as the input of the second encoder. That is, the first one is used as the generator and the second one is used as the discriminator to perform the adversarial discrimination process.
[0088] 4) Design a two-stage training method, including:
[0089] Stage 1: The first half (i.e., encoding part) of the two autoencoder models are shared, using a common encoder network:
[0090] AE 1 =D 1 (E(X)),AE 2 =D 2 (E(X)) (7)
[0091] The input data X is compressed by the encoding part of the autoencoder to the latent space Y, and then reconstructed by the two encoders respectively until each autoencoder is trained to reconstruct the input vector (e.g. Figure 3 ), that is, minimizing the following two equations:
[0092]
[0093] Stage 2: Two autoencoders are trained in an adversarial manner, AE 1 Trying to trick AE 2 , and AE 2 The goal is to learn to distinguish which data is real and which data is reconstructed. 2 Able to identify real data and data from AE 1 Data, training AE 1 Tricking AE 2 , from AE 1 The output data is compressed again by the encoder to Y, and then by AE 2 Reconstruction, using the idea of adversarial training, AE 1 The goal is to minimize AE 2 The difference between the output and X, AE 2 The goal is to maximize this difference (such as Figure 4 ).AE 1 Is the training successful in deceiving AE?2 , while AE 2 It is trained to distinguish between real data and data from AE 1 Output the reconstructed data:
[0094]
[0095] The error loss function can be further expressed as:
[0096]
[0097] In this training architecture, the autoencoder serves a dual purpose. 1 Minimize the reconstruction error of X (stage 1), and also make X and AE 2 About AE 1 The output reconstruction error is the smallest (stage 2). 2 , and AE 1 Similarly, it minimizes the reconstruction error of sample X (stage 1), but it then makes AE 1 The reconstructed input data has the largest error (stage 2). The dual training objectives of each autoencoder can be expressed as a linear combination of equations (8) and (10):
[0098]
[0099]
[0100] Where n represents the training cycle. It should be noted that AE 2 It is not a discriminator of the adversarial network in the strict sense, because if its input is the original data, then equation (8) should be used to calculate the loss. 1 When reconstructing, its loss is calculated using equation (10). It should be noted that in the parameter update during the training process, a related optimization algorithm can be used. Here, a small batch optimization algorithm based on Adam optimization and gradient descent optimization is used.
[0101] 5) Design attack detection algorithms (such as Figure 5 )
[0102] According to the training methods of stage 1 and stage 2 in step 4) above, in the detection phase (i.e., the testing phase), the anomaly score is defined as:
[0103]
[0104] Where α+β=1 and is used to parameterize the trade-off between false positives and true positives. If α is greater than β, the number of true positives and false positives will be reduced. On the contrary, if α is taken to be less than β, the number of true positives will increase, but the number of false positives will also increase. α<β is represented as a high-sensitivity detection scenario, and α>β is represented as a low-sensitivity detection scenario. This parameterization scheme has great industrial significance. It allows a set of different sensitivity anomaly scores to be obtained during inference using a single trained model. A larger α corresponds to a greater emphasis on AE in the anomaly score. 1 The reconstruction error of the autoencoder, and a larger β corresponds to a greater emphasis on the AE 2 Reconstruction error of the autoencoder. The detection sensitivity can be readjusted without retraining the model. The parameterizable adjustment of α and β allows the sensitivity of the detection model to meet the requirements of a wide variety of production environments.
[0105] 6) Design an attack detection method based on a two-stage autoencoder
[0106] The entire attack detection method is divided into three steps (refer to Figures 3 to 5 ):
[0107] Step 1: Data preprocessing. The training data set is normalized and divided into time series windows of length K. A univariate time series contains only one variable at each moment, while a multivariate time series contains multiple variables at each moment. 1 ,x 2 ...,x T},x∈R m In order to mathematically model the dependency between the current moment and the previous moment, we define X again: t , given a time window length K and time t: X t ={x t-(K-1) ,x t-(t-2) ,...,x t-1 ,x t The original time series Γ can be transformed into a time window sequence X = {X 1 ,…,X T} as training input.
[0108] Step 2: Train the model. The model is trained using the method designed in step 4. Model training is performed offline to capture the normal behavior of multivariate time series over a period of time and generate anomaly discrimination scores for each time window. Note that the selected time period does not contain a large amount of abnormal data after an attack.
[0109] Step 3: Attack detection. This step is performed using the model trained in step 2 (online). As new time windows are formed, the model generates anomaly scores Sc for each window. t , if it is higher than the given threshold λ, the time period corresponding to the new time window is the abnormal time period under attack.
Claims
1. A two-stage autoencoder-based industrial cyber-physical system attack detection method, It is characterized in that The following steps are involved: 1) Establish a multi-device, multi-link FDI attack model; 2) Introducing autoencoder technology; 3) Construct a generative adversarial model based on autoencoder; 4) Design a two-stage training method; 5) Design attack detection algorithm; 6) Design an attack detection method based on a two-stage autoencoder; The step 1) specifically includes: multi-link and multi-device FDI attacks are divided into the following two types according to their occurrence locations: ① Controller-actuator link or device attack: where δ 1 is the attack vector, u 1 is the output value of the controller, is the input value of the actuator, that is, the received value. In this type of attack, the attacker tampers with the command data of the controller. The injected attack data is specifically used to affect the task execution of the actuator, making it perform incorrect operations that appear to be correct, thereby deceiving the controller. ②Sensor-controller link or device attack: where δ 2 is the attack vector, y 1 is the sensor output, is the input value of the controller, that is, the actual received value. This type of attack mainly involves the attacker tampering with the information returned by the sensor to the controller, interfering with the controller's data reception and thus affecting the issuance of its adjustment instructions, deceiving the controller and causing it to issue control adjustment instructions that are inconsistent with the actual situation in the next step. The actuator and sensor operation data generated by these two attacks can be viewed as long-term time series vectors: In step 2), the autoencoder is an unsupervised neural network algorithm. The autoencoder can learn the implicit features of the input data vector, so that it can be transformed from high-dimensional data into multi-dimensional data, that is, data dimension reduction. This step is called encoding. At the same time, the new features learned can also reconstruct the original input data, which is called decoding. In addition to dimensionality reduction, the autoencoder can also play the role of a feature extractor. Here, the autoencoder is used as a feature extractor to learn the features of the multi-dimensional time series data of sensors and actuators, so that it can reconstruct the operating data of sensors and actuators when the system is in normal operation. Building an autoencoder requires three tasks: building an encoder, building a decoder, and setting a loss function to measure the information lost due to encoding compression. The encoder is responsible for receiving the input vector X and converting the input into a reduced-dimensional encoding vector Y through the h function: Y=h(X) (4) The decoding step takes the encoded vector Y as its input and obtains the reconstructed vector through the function f: Define the error err as the sum of the original input X and the reconstructed vector The difference between The goal of training is to reduce the mean squared error (MSE); The step 3) specifically includes: first, we need to understand the idea of generative adversarial networks. Generative adversarial networks (GAN) are a deep learning model composed of a generator G and a discriminator D. First, G learns the probability distribution of a given input data set and generates artificial data that follows the same distribution. Then, D calculates the similarity gap between the data generated by G and the real data. The smaller the gap value, the more similar the generated fake data is to the real original input. The entire adversarial learning process of GAN can be regarded as a game process about optimizing the maximum and minimum values of the objective function V(D,G): As can be seen from formula (6), for the generator G, it is necessary to deceive the discriminator D as much as possible, so it is necessary to maximize the discrimination probability D(G(z)) of D for the generated samples, that is, minimize log(1-D(G(z))); and for D, its goal is to distinguish the forged generated samples from the real samples as much as possible, so it is necessary to maximize log(1-D(G(z))); According to the construction steps of the autoencoder described in step 2), two autoencoders need to be constructed according to the described steps. After both are trained, the reconstructed output decoded by one of the encoders is used as the input of the second encoder; that is, the first one is used as a generator and the second one is used as a discriminator to perform an adversarial discrimination process; The step 4) specifically includes: Stage 1: The first half of the two autoencoder models, i.e. the encoding part, are shared, using a common encoder network: AE 1 =D 1 (E(X)),AE 2 =D 2 (E(X)) (7) The input data X is compressed into the latent space by the encoding part of the autoencoder, and then reconstructed by the two encoders respectively until each autoencoder is trained to reconstruct the input vector, that is, to minimize the following two equations: Stage 2: Two autoencoders are trained in an adversarial manner, AE 1 Trying to trick AE 2 , and AE 2 The goal is to learn to distinguish which data is real and which data is reconstructed; this stage requires AE 2 Able to identify real data and data from AE 1 Data, training AE 1 Tricking AE 2 , from AE 1 The output data is compressed into the latent space by the encoder again, and then 2 Reconstruction; Using the idea of adversarial training, AE in this stage 1 The goal is to minimize AE 2 The difference between the output and X, and AE 2 The goal of AE is to maximize this difference; 1 Training to successfully deceive AE 2 , while AE 2 It is trained to distinguish between real data and data from AE 1 Output the reconstructed data: The error loss function is further expressed as: In this training architecture, the autoencoder serves a dual purpose; 1 Minimize the reconstruction error of X and make X and AE 2 About AE 1 The output reconstruction error is the smallest; as for AE 2 , and AE 1 Similar to AE 2 To minimize the reconstruction error of sample X, but AE 2 Later, we will use AE 1 The reconstructed input data has the largest error; the dual training objectives of each autoencoder can be expressed as a linear combination of equation (8) and equation (10): Where n represents the training cycle; AE 2 It is not a discriminator of adversarial network in the strict sense, because if AE 2 If the input is the original data, then the loss should be calculated using formula (8); when AE 2 The input is AE 1 When reconstructing, AE 2 The loss is calculated using formula (10); the parameter update during the training process uses a small batch optimization algorithm based on Adam optimization and gradient descent optimization; The step 5) specifically includes: according to the training methods of the stages 1 and 2, in the detection stage, i.e. the test stage, the anomaly score is defined as: where α+β=1 and is used to parameterize the tradeoff between false positives and true positives; if α is greater than β, the number of true positives and false positives will be reduced; conversely, if α is less than β, the number of true positives will be increased, but the number of false positives will also be increased; α<β represents a high-sensitivity detection scenario, and α>β represents a low-sensitivity detection scenario; allows a single trained model to obtain a set of different sensitivity anomaly scores during inference; a larger α corresponds to placing more emphasis on AE in the anomaly score 1 The reconstruction error of the autoencoder, and a larger β corresponds to a greater emphasis on the AE 2 Reconstruction error of the autoencoder; the detection sensitivity can be readjusted without retraining the model; the parameterizable adjustment of α and β allows the sensitivity of the detection model to meet the requirements of a variety of production environments; The step 6) specifically includes: the entire attack detection method is divided into three steps: Step 1: Data preprocessing; the training data set is normalized and divided into time series windows of length K; a univariate time series contains only one variable at each moment, while a multidimensional time series contains multiple variables Γ = {x 1 ,x 2 ...,x T },x∈R m In order to mathematically model the dependency between the current moment and the previous moment, we define X again: t , given a time window length K and time t: X t ={x t-(K-1) ,x t-(K-2) ,...,x t-1 ,x t }; The original time series Γ can be transformed into a time window sequence X = {X 1 ,...,X T } as training input; Step 2: Train the model. Use the method designed in step 4 to train the model. The training is done offline to capture the normal behavior of the multivariate time series over a period of time and generate anomaly discrimination scores for each time window. Be careful not to select data that does not contain a large amount of abnormal time periods after attacks. Step 3: Attack detection; this step uses the model trained in step 2 to execute online. As new time windows are formed, the model generates anomaly scores Sc for each window. t , if it is higher than the given threshold λ, the time period corresponding to the new time window is the abnormal time period under attack.
Citation Information
Patent Citations
Hierarchical network attack identification and unknown attack detection method based on deep learning
CN110691100A
Multi-point FDI attack detection method for industrial information physical system of generative adversarial network
CN113281998A